{"id":"CVE-2026-89818","aliases":[],"url":"https://o3.security/vulnerability/CVE-2026-89818","summary":"In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amdgpu/vcn: fix integer overflow in dec_msg buffer count check\n\nIf the supplied msg[2] (num_buffers) is 0x3FFFFFFF,…","details":"In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amdgpu/vcn: fix integer overflow in dec_msg buffer count check\n\nIf the supplied msg[2] (num_buffers) is 0x3FFFFFFF, the expression\n6 + num_buffers * 4 wraps to 2 and the bounds check passes, letting\nthe parser loop far past the end of the message BO. Triggering it\nadditionally requires a ~4GiB mapping so that msg[1] survives the\nearlier \"header does not fit in BO\" check.\n\nRewrite the test in division form, which is overflow-free by\nconstruction. Also update the message to reflect that msg is invalid.","published":"2026-09-16T10:30:50.946Z","modified":"2026-09-16T10:30:50.946Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[],"fix":null,"references":[{"type":"WEB","url":"https://git.kernel.org/stable/c/c2340281be4ddacb8c203e2bce59b126d1d6c4c8"},{"type":"WEB","url":"https://git.kernel.org/stable/c/6dceaeceaa7c8396339f3ea34b0110cb912ca61b"},{"type":"WEB","url":"https://git.kernel.org/stable/c/47799e1f893d47d8af231710a61065e3ec8a13e8"},{"type":"WEB","url":"https://git.kernel.org/stable/c/7e28853c78c20bb8ba4c1dba702430cd05e09f76"},{"type":"WEB","url":"https://git.kernel.org/stable/c/9ae19bd60891bea0a7b7504cc8dbfe74570ac3b3"},{"type":"WEB","url":"https://git.kernel.org/stable/c/4d7390530853eb7befda9cc786e4c86e8ad7ac9e"}],"provenance":{"sources":["OSV.dev","NVD","FIRST.org (EPSS)"],"lastVerified":"2026-09-16T10:30:50.946Z"}}